Student records
The offices that own the official student record. Applications and transcripts arrive from Slate, Common App, and the SIS; award files run through verification and appeals; transcripts release inside the 45-day FERPA window.
The Feith Platform for Higher Education runs admissions, financial aid, the registrar, sponsored research, and the eight other offices that own records, on the same architecture that manages federal agencies' permanent records. Every access writes to one append-only audit log.
FERPA · GLBA · HIPAA · NIST 800-171 · state public records · Title IX, all on one platform. Records engine built to DoDM 8180.01, the current DoD standard, with DISA-JITC testing heritage under the retired DoD 5015.02 · FIPS 140-3 encryption · FedRAMP Moderate authorized on the federal side · built and owned in Fort Washington, PA.
FERPA governs the student record. GLBA governs the aid file. NIST 800-171 covers anything CUI that arrives with a federal grant. State law and Title IX layer their own rules on top. And the records don't sit in one system.
They live in Banner, PeopleSoft, Workday, M365, Google Workspace, file shares, and the paper folders some offices still keep, and the records officer is responsible for all of it. Feith takes responsibility for the records the moment they exist. Capture normalizes the metadata, the vault holds the authoritative copy, the audit log records every access, and retention runs against each office's schedule.

Twelve departmental workflows, organized into five family modules, each on the same vault, identity layer, and audit log, each shipping with the document types, workflows, and retention rules the family actually uses.
The offices that own the official student record. Applications and transcripts arrive from Slate, Common App, and the SIS; award files run through verification and appeals; transcripts release inside the 45-day FERPA window.
Grant files, IRB and IACUC records, and the CUI that arrives with a federal research contract, all held in one campus vault.
Personnel files, tenure dossiers, search-committee records, and faculty contracts, plus gift records, donor files, and planned-giving documentation, separated from FERPA-protected records at the access layer where policy requires it.
Open-records requests, subpoena response, and e-discovery, alongside Title IX investigation files that need separated roles and a preserved evidence chain.
Counseling, health-services, vaccination, and accommodation records, held as FERPA treatment records, which the HIPAA Privacy Rule expressly excludes from protected health information, with HIPAA reaching the health center's non-student patients and ADA accommodation records kept separate.
Feith treats FERPA as a structural requirement. Every access to a student record writes to an append-only log, the 45-day access window is a tracked workflow, and the school-official exception is logged with the determination that justified it.
The clock starts on the request. The package returned to the requester is itself recorded.
Federally-funded research carries federal records obligations: CUI markings, NIST 800-171 controls, ITAR and EAR export controls, CMMC posture for DoD work. Feith handles them on the same platform that handles your registrar's transcripts. The research office stops standing up parallel systems to satisfy compliance.
State public-records requests arrive with a clock attached. Title IX files have to be retained, redacted, disclosed selectively, and held for years. Both run on the same vault, with the same exemption logic and redaction tooling as Feith's federal FOIA Workbench.
Open-records and sunshine laws apply to public universities and, in specific contexts, to private institutions. Feith runs each request as a tracked case: intake, scoping, search, redaction, exemption application, release package, response letter.
The Title IX framework has shifted repeatedly since 2020. Feith doesn't pin to any one version of the rule: it holds investigation files with need-to-know access, separates investigator and decision-maker roles, keeps an evidence chain, and applies litigation hold the moment a notice is logged.
Feith runs on the identity layer your campus already uses, and runs lifecycle and audit across records wherever they live, without forcing a migration.
SAML, Shibboleth, AD / LDAP, and MFA: the login your campus already uses, with role attributes derived from the SIS. Need-to-know access is enforced per record, per field, per workflow step.
Append-only, hash-verified, anti-tamper, with Splunk / SIEM forwarding. The same audit architecture built for federal records — DoDM 8180.01 today, DISA-JITC tested against DoD 5015.02 from 2002 until that standard was retired — holds your campus access log too.
Connectors capture from M365, Google Workspace, file shares, and the SIS, and a governed copy lands in the vault with its metadata intact. Your teams keep working in the tools they already use; retention, holds, disposition, and audit run against the authoritative copy in the vault.
Most campuses come from OnBase, Banner Document Management, Laserfiche, Perceptive Content, or a homegrown stack. The migration runs in three phases, one at a time, so the path stops being all-or-nothing.
Records flow into Feith from your existing systems while your incumbent ECM keeps running. Identity and audit consolidate first; the new vault carries everything that arrives after go-live without touching the legacy archive.
No system retires in this phase.
Pick the office with the most pain. Sponsored Programs and Financial Aid are common first choices. Move that office's workflow, then repeat on a schedule the campus controls. Each cutover is independent.
Sequenced to your priorities, one department at a time.
Some campuses retire the incumbent ECM once active workflows have moved; others keep it as a read-only archive. Either way, the Feith vault holds the authoritative copy of anything still in flight.
When the campus is ready. The decision is reversible.
A state university CIO doesn't have to argue the architecture from first principles. The vault, audit log, identity layer, and lifecycle services under the platform are the same components that align to the National Archives' Universal ERM requirements and are built to the Department of Defense's records standard.
A walkthrough of your actual records workflow, showing what Feith does in the office with the most pain.
Thanks. We'll reach out shortly to schedule your walkthrough.